PT-2026-65767 · Apache Airflow · Apache Airflow Fab Provider

·

CVE-2026-59243

·

Published

2026-03-18

·

Updated

2026-08-05

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-fab versions prior to 3.7.3
Description The FAB auth manager's Azure AD OAuth login process failed to verify the signature of the ID token by default, as the verify signature variable was set to False. This allows an attacker to bypass authentication and log in as any user, including those with Admin privileges, by providing a forged or unsigned ID token (using alg:none) to the OAuth callback.
Recommendations Upgrade to version 3.7.3.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10701
CVE-2026-59243

Affected Products

Apache Airflow Fab Provider